UK remote
VP, Security Operations
About this role
Sportradar · Global · Reports to the EVP, Information Security (Group CISO), Privacy and Enterprise Risk This is a hands-on leadership role. You need to be technical, in the detail, and able to lead an incident bridge. You will run a global function and own Security Operations end to end: the SOC, incident response, detection engineering and threat intelligence, along with the people and platforms behind them. THE CHALLENGE: Own incident response.
Preparation, triage, containment, eradication, and the post-incident reviews that make the next incident smaller. You will lead major incidents personally and set the standard for what good looks like. Build the SOC we need next, not the one we have. Evolve the operating model, the on-call structure, the tooling and the automation. You will have built a SOC before, either from scratch or through a major rebuild. Treat detection engineering as an engineering discipline.
Detections as code: versioned, tested, tuned, and mapped to the threats that actually target us rather than a vendor's default rule pack. You will drive the coverage roadmap across our cloud estate and applications, and you know the difference between a thousand alerts and one good one. Make threat intelligence earn its keep. Build an intel capability that changes what we hunt for, what we detect, and what we brief to leadership.
Be the voice of operational reality. At the leadership table, you are the person who knows what is happening on the ground, and says so. You will work closely with engineering, product security and the wider InfoSec leadership so that what we build is defensible and what we defend is understood. Own operational effectiveness. Define and improve measures that matter: detection coverage, investigation quality, time to detect and contain, escalation effectiveness, and whether lessons from incidents get implemented.
ABOUT YOU: Deep, current incident response experience. You have personally led the response to serious incidents rather than observing them from a governance layer. You have built a SOC: stood one up, or rebuilt one that wasn't working. The operating model, the hiring, the tooling, the metrics. You know what the first 90 days look like because you have lived them. Technical, with a solid grounding in cloud. You understand how modern cloud environments (AWS, GCP, Azure) are attacked and defended, including identity, logging, lateral movement and containment, and how incident response works within them.